Surveillance Audit
A periodic audit conducted by a certification body between initial certification and recertification to verify that an organization continues to maintain and improve its management system in conformity with the standard. Surveillance audits typically occur annually during the three-year certification cycle.
Surveillance audits are a mandatory part of the ISO certification lifecycle, designed to ensure that certified organizations maintain their management system between full certification audits. After an organization achieves ISO 27001 certification, the certification body schedules surveillance audits — typically one per year — during the three-year certification period. Unlike the full two-stage certification audit, surveillance audits are shorter in duration and focus on a subset of the management system. However, they are comprehensive enough to provide confidence that the ISMS continues to operate effectively and that the organization is addressing any previously identified issues.
Surveillance audits typically cover several mandatory elements regardless of the specific scope: the results of internal audits and management reviews, the status of corrective actions from previous audit findings, handling of complaints and feedback, the effectiveness of the ISMS in achieving its objectives, progress on planned improvements, and any changes that may affect the management system. Beyond these mandatory elements, the certification body selects additional areas to audit, progressively covering the entire scope of the ISMS across surveillance and recertification audits. If significant nonconformities are identified during a surveillance audit, the certification body may increase audit frequency, reduce the scope of certification, or suspend the certificate until the issues are resolved.
For organizations maintaining ISO 27001 certification, surveillance audits should not be viewed as surprise inspections but as a regular cadence of external validation. The best approach is to maintain continuous audit readiness through ongoing internal audits, regular management reviews, prompt closure of corrective actions, and consistent documentation practices. Organizations should prepare for each surveillance audit by reviewing the audit plan provided by the certification body, ensuring relevant evidence is current and accessible, and briefing personnel who will be interviewed. The surveillance audit results also provide valuable external perspective on the organization's ISMS performance and can highlight areas for improvement that internal processes may have missed.
Related frameworks
Related terms
Certification Body
An accredited third-party organization authorized to conduct audits and issue certifications confirming that an organization's management system conforms to a specific standard, such as ISO 27001. Certification bodies must be accredited by a national accreditation body to ensure their competence and impartiality.
External Audit
An independent assessment conducted by a third-party auditor or certification body to evaluate an organization's compliance with a specific standard or framework, such as ISO 27001 certification audits or SOC 2 examinations.
Internal Audit
A systematic, independent evaluation conducted by an organization's own personnel or contracted auditors to assess the effectiveness of its management system, controls, and processes against defined criteria such as ISO 27001 requirements or internal policies.
Information Security Management System
A systematic framework of policies, processes, and controls that an organization establishes to manage and protect its information assets. An ISMS addresses people, processes, and technology to ensure the confidentiality, integrity, and availability of information.
Nonconformity
A failure to fulfill a requirement of a standard, policy, procedure, regulation, or contractual obligation. In the context of management systems like ISO 27001, nonconformities are categorized as major (systemic failure or significant gap) or minor (isolated or partial failure).
Assess your compliance posture
Run a free self-assessment for ISO 27001, SOC 2, GDPR, NIS2, or Tech DD and see exactly where you stand.
Start free assessment